Compliance retention field guide

How Long Should Call Recordings Be Kept? GDPR, HIPAA, MiFID II, and Dodd-Frank

Replace a blanket “keep forever” setting with a plain-language schedule based on purpose, applicable rules, start events, holds, and verified deletion.

Published Updated 9 minute read Primary sources reviewed
Recorded calls assigned to policy-based retention, legal hold, retrieval, and deletion controls

Signal path

Recording categoryRetention ruleDeletion or hold

Where call-recording.com intervenes

From technical requirement to working recording

Call Observe provides retention controls, organization-scoped access, search, playback, audit history, and delivery evidence so customers can apply a legally approved schedule to supported recordings.

Short answer

There is no single retention period for every business call. Keep each recording for the shortest period that satisfies its approved purpose and any law, regulation, contract, dispute, or legal hold that applies.

GDPR does not set one number. HIPAA does not set a general medical-record retention period. MiFID II specifies five years for its in-scope recordings and allows extension up to seven years at a competent authority's request. U.S. commodities recordkeeping depends on the regulated entity, activity, record class, and current CFTC rule.

The correct output is a written schedule by recording category—not a vendor default such as “keep everything forever.”

Retention periods at a glance

Framework or purposePractical ruleWhat to verify
GDPRKeep personal data no longer than necessary for the defined purpose, subject to justified legal obligations or claimsPurpose, lawful basis, necessity, start event, deletion, rights, holds
HIPAANo general HIPAA medical-record period; separate HIPAA documentation rules and other federal or state record rules may applyRecord type, state law, designated-record-set handling, BAA, safeguards, disposition
MiFID IIFive years for Article 16(7) records; up to seven when requested by the competent authorityIn-scope activity, start event, durable record, ready retrieval, extension, holds
Dodd-Frank and CFTC rulesUse the current rule for the entity, activity, and record class; do not apply one headline number to every recordRegistration status, oral versus written records, related transaction, accessibility, current 17 CFR requirements
Quality and trainingUse a short period justified by the operating purpose unless another duty appliesSampling window, complaint period, employee notice, deletion evidence
Disputes and legal holdsSuspend routine deletion only for the records and period covered by the holdAuthority, scope, custodian, start, release, resumed deletion

This table is a starting point, not legal advice. Counsel and records-management owners should approve the schedule.

What does GDPR require for retention?

The GDPR includes storage limitation: personal data should be kept in identifiable form no longer than necessary for the purpose, subject to limited exceptions and appropriate safeguards.

A GDPR retention decision should answer:

  • Why is the call recorded?
  • Which people and call types are necessary?
  • When does the period start?
  • Why is the selected period necessary?
  • Does a legal obligation or claim justify a longer period?
  • How are access, erasure, restriction, objection, and legal holds handled?
  • How is deletion from active storage, replicas, exports, and vendor systems verified?

“Storage is cheap” is not a purpose. Different purposes should normally have different schedules.

Does HIPAA require recordings to be kept for six years?

Not as a general rule. 45 CFR § 164.316 has a six-year retention rule for specified Security Rule documentation, but that does not mean every patient call recording must be kept for six years.

HHS says the Privacy Rule does not require medical records to be retained for a specific period. State law, Medicare or Medicaid rules, professional requirements, contracts, litigation, or the role of the recording in a designated record set may lead to a different result.

Classify the recording first. A billing call, clinical triage call, complaint, authorization, and workforce training sample may not have the same retention rule. The HIPAA call-recording guide covers the wider PHI and BAA controls.

What is the MiFID II period?

MiFID II Article 16(7) requires the relevant records to be retained for five years and, when requested by the competent authority, up to seven years.

The period alone is not enough. The firm also needs complete capture, prior notice, protected original records, ready accessibility, monitoring, and a way to provide the record to a client on request. Apply the period only to the activities that the approved MiFID scope includes. See the MiFID II Cisco call-recording guide for the full control set.

What should a Dodd-Frank schedule say?

Dodd-Frank is often used as shorthand for several CFTC swap recordkeeping duties. The current 17 CFR § 23.202 identifies records that swap dealers and major swap participants must make and keep. 17 CFR § 23.203 points to applicable retention and accessibility requirements.

Do not copy an old blog's number into production. Confirm the firm's current registration status, the communication type, its relationship to a transaction, the current incorporated retention rule, accessibility requirements, and any preservation order. The Dodd-Frank call-recording guide provides a more detailed starting point.

How should PCI data affect retention?

Payment-card data should usually be prevented from entering audio in the first place. PCI DSS prohibits storage of sensitive authentication data such as card verification codes after authorization. Keeping a long recording does not justify keeping prohibited data inside it.

Use pause and resume, DTMF suppression, secure payment capture, redaction, or another validated method to keep account data out of recordings and transcripts. If prohibited data is discovered, follow the approved incident and secure-deletion process. The PCI DSS call-recording guide covers this boundary.

Build a schedule the platform can enforce

For each recording category, document:

  1. category and owner;
  2. business purpose and legal basis;
  3. people, numbers, queues, and call types;
  4. start event and normal period;
  5. minimum and maximum requirements;
  6. access and export rules;
  7. legal-hold trigger and release process;
  8. deletion method and evidence;
  9. treatment of transcripts, summaries, backups, and exports; and
  10. review date and approving authority.

Keep the schedule in plain language. An administrator should be able to map each rule to a real platform configuration.

How Call Observe supports retention operations

Call Observe provides configurable retention, organization-scoped access, search, playback, audit history, and visible delivery state for supported recording paths. These controls help a customer apply an approved schedule and retrieve records during their valid life.

The customer still needs to define the schedule, assign recordings to the correct rule, govern exported copies, authorize holds, and confirm deletion. The compliance recording and chain-of-custody guide covers those operating controls in more detail.

Bottom line

Retention should be specific, justified, and enforceable. Separate regulated recordings from training, service, dispute, and security use cases. Apply the required minimum, avoid unnecessary indefinite storage, suspend deletion for valid holds, and resume deletion when the hold ends.

Call Observe supplies the platform controls; the customer and its advisers supply the legally approved schedule.

Where call-recording.com intervenes

From technical requirement to working recording

Call Observe provides retention controls, organization-scoped access, search, playback, audit history, and delivery evidence so customers can apply a legally approved schedule to supported recordings.

Source ledger

Primary references and technical evidence

Validate version-specific commands, legal scope, and policy decisions against the current source applicable to your environment.

Legal and compliance content is general information, not legal advice. Cisco behavior and commands vary by product release, platform, firmware, and call flow.